CVE-2025-32711
M365 Copilot Information Disclosure Vulnerability
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.3EPSS 5.8%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Lifecycle
11 Jun 2025Published on NVD
27 Jun 2025Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Microsoft 365 Copilotpublic PoCs found — 3
githubgithub.com/daryllundy/cve-2025-32711★ 3githubgithub.com/TreRB/markdown-exfil-tester★ 0githubgithub.com/Danielossai12/aisecplus-week01-danielossai★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →